CVEFeed Newsroom – Latest Cybersecurity Updates
The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.
-
The Hacker News
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw h ...
-
The Hacker News
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 cand ...
-
The Hacker News
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses ...
-
The Hacker News
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough ...
-
security.nl
WinRAR-lek gebruikt bij ransomware-aanvallen, meldt Amerikaanse overheid
Een bekende kwetsbaarheid in het populaire archiveringsprogramma WinRAR wordt gebruikt bij ransomware-aanvallen, zo meldt het Amerikaanse cyberagentschap CISA. Het beveiligingslek, aangeduid als CVE-2 ...
-
security.nl
Apple dicht Screen Sharing-lek dat aanvaller toegang tot Macs kan geven
Apple heeft een beveiligingsupdate voor macOS uitgebracht die een kwetsbaarheid verhelpt waardoor ongeauthenticeerde aanvallers toegang tot Macs kunnen krijgen. Het beveiligingslek (CVE-2026-65400) is ...
-
OS X Daily
Security Updates MacOS Tahoe 26.6.1, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9 Released for Mac
Apple has released security updates for MacOS Tahoe 26.6.1, MacOS Sequoia 15.7.9, and MacOS Sonoma 14.8.9, each addressing the same security flaw relating to the Screen Sharing service where an attack ...
-
The Hacker News
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applie ...
-
The Hacker News
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issue ...
-
The Hacker News
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense ...